Expert · Chapter 03 · ISSMP

ISSMP — Information Systems Security Management Professional

Security Program Leadership: CISO Role, ERM, Threat Intelligence & Resilience Management

Quản lý chương trình bảo mật ở cấp doanh nghiệp: từ CISO leadership và board reporting, Enterprise Risk Management (ISO 31000/COSO), đến threat intelligence program, incident management, BCP/DR theo ISO 22301, và compliance program management. Concentration dành cho security manager và CISO.

Mục tiêu chương / Learning objectives

1. Domain 1 — Leadership & Business Management / Lãnh đạo & quản lý kinh doanh

1.1. CISO Role Evolution — From Technical to Business Executive

CISO hiện đại không còn là "Chief Firewall Officer" — là một business executive chịu trách nhiệm về information risk của toàn tổ chức. Sự tiến hóa: CISO 1.0 (1990s-2000s) — kỹ thuật, báo cáo cho CTO/CIO, focus vào compliance checkbox; CISO 2.0 (2010s) — risk management, báo cáo cho CIO/CFO, quantify risk bằng tiền; CISO 3.0 (hiện tại) — business strategist, báo cáo thẳng lên CEO hoặc Board, là strategic partner của business units.

Board Reporting: Báo cáo cho Board phải: (1) Business language — thay vì "CVE-2024-XXXX với CVSS 9.8" hãy nói "Lỗ hổng này cho phép attacker đánh cắp toàn bộ customer database — tương đương exposure $50M theo FAIR analysis". (2) Trend, không phải snapshot — Board quan tâm trend: "Security posture đang cải thiện hay suy giảm?" (3) Decisions needed — mỗi board report phải end với "Board cần approve X budget/policy để address Y risk." (4) Benchmark — so sánh với peers: "Chúng ta chi 4% IT budget cho security vs. industry average 7% cho BFSI sector."

1.2. Security Program Business Case — ROI & Risk Framing

Cost of Breach framing: IBM Cost of Data Breach Report (annual) cung cấp industry benchmarks: global average $4.88M per breach (2024), BFSI sector $6.08M, healthcare $9.77M. CISO sử dụng các số liệu này để frame security investment: "Nếu chúng ta không đầu tư $2M vào MFA và EDR, expected annual loss từ credential-based attacks là $3.5M theo FAIR analysis — ROI = 75%."

Security Budget Prioritization: Hai framework phổ biến: (1) Risk-based — phân bổ budget theo risk reduction per dollar: controls với highest risk reduction per $ invested được ưu tiên (ví dụ MFA có ROI bảo mật cao nhất trong hầu hết tổ chức). (2) Maturity-based — đầu tư để nâng maturity level từ thấp lên trung bình trước khi optimize high-maturity areas. Trong thực tế, CISO kết hợp cả hai.

OpEx vs. CapEx for Security: Cloud-based security tools (SaaS SIEM, CASB, ZTNA) thường là OpEx — dễ get approved vì không cần capital investment. On-prem tools là CapEx. CISO cần hiểu financial implications: CapEx thường yêu cầu higher approval threshold, nhưng có thể depreciate. Khi pitching to CFO, frame OpEx tools bằng "per user per month" cost so sánh với "cost of one incident."

1.3. Security Governance — RACI & OKRs for Security

Security Steering Committee: Thành phần: CISO (chair), CIO, CFO, CRO (Chief Risk Officer), General Counsel, business unit heads. Meeting frequency: quarterly hoặc monthly. Agenda: risk posture update, major incidents debrief, policy exceptions requiring executive approval, budget adjustments. Minutes phải được documented và signed — governance evidence cho auditors.

RACI Matrix for Security: Phân định rõ Responsible (làm), Accountable (chịu trách nhiệm cuối), Consulted (được tham vấn), Informed (được thông báo) cho từng security activity. Ví dụ: Patch Management — R: IT Operations, A: CISO, C: System Owners, I: Security Steering Committee. RACI ngăn "That's not my job" khi incident xảy ra.

OKRs (Objectives and Key Results) for Security: Ví dụ O: "Giảm attack surface đáng kể trong Q3 2026." KR1: Giảm mean time to patch critical vulnerabilities từ 45 ngày xuống 10 ngày. KR2: Đạt 98% EDR coverage trên tất cả endpoints (hiện tại 84%). KR3: Eliminate 100% shared admin accounts và replace bằng PAM-managed accounts. OKRs align security với business outcomes và measurable.

1.4. Security Maturity Models

CMMI for Security (Capability Maturity Model Integration): Áp dụng CMMI-DEV hoặc CMMI-SVC vào security processes. 5 maturity levels tương tự SSE-CMM nhưng focus vào management processes. C2M2 (Cybersecurity Capability Maturity Model) của DOE có 10 domains và 4 maturity indicator levels (MIL0-MIL3) — thường dùng cho energy sector. BSIMM (Building Security In Maturity Model) là benchmark cho software security practice — đo lường tổ chức so với peers trong cùng industry vertical.

Merger & Acquisition Security Due Diligence: M&A security phải xảy ra TRƯỚC khi deal close — không phải sau. Pre-close: cyber due diligence (vulnerability assessment, review of past incidents, compliance status, third-party risks, IP protection). Day-1 security controls: isolate acquired network, implement MDM cho devices, enforce VPN, review admin accounts. Post-close integration (6-12 months): migrate vào parent identity provider, apply security baseline, consolidate tooling.

2. Domain 2 — Systems Lifecycle Management / Quản lý vòng đời hệ thống

2.1. Enterprise Security Program Lifecycle

Security program lifecycle gồm 5 phases liên tục: Assess (baseline current state — vulnerability assessment, penetration test, maturity assessment, gap analysis vs. target framework) → Plan (develop roadmap — prioritize initiatives theo risk/impact, define 1-year và 3-year plans, secure budget) → Implement (execute roadmap — deploy controls, train people, update processes) → Operate (run security operations — SOC, incident response, patch management, vulnerability management) → Evaluate (measure effectiveness — metrics, KPIs, audit, red team) → back to Assess.

2.2. Security Roadmap Development

3-Year Security Transformation Roadmap structure: Year 1 — Establish Foundation: Fix critical vulnerabilities (CAT I findings), deploy MFA, implement EDR, establish SIEM, document policies. Year 2 — Mature Capabilities: Deploy PAM, implement ZTNA, mature SOC (add threat hunting), third-party risk program, security training program. Year 3 — Optimize & Lead: Automate security operations (SOAR), quantitative risk management (FAIR), red team program, security product integration with DevSecOps.

Quick Wins vs. Strategic Initiatives: Quick wins (0-90 days) — high impact, low complexity: MFA cho all admins, disable inactive accounts, patch top-10 critical CVEs, enable logging. Strategic initiatives (6-18 months) — high impact, high complexity: Zero Trust implementation, PAM deployment, SIEM + SOAR deployment. CISO phải deliver quick wins sớm để build credibility với Board trước khi ask for strategic investment.

3. Domain 3 — Risk Management / Quản lý rủi ro

3.1. Enterprise Risk Management — ISO 31000 & COSO ERM

ISO 31000:2018 (Risk Management — Guidelines) định nghĩa 8 principles, framework components, và 6-step risk management process: (1) Communication and consultation → (2) Scope, context, and criteria → (3) Risk assessment (identification, analysis, evaluation) → (4) Risk treatment → (5) Monitoring and review → (6) Recording and reporting. ISO 31000 là framework-agnostic — áp dụng cho mọi loại risk.

COSO ERM (2017) — Enterprise Risk Management — Integrating with Strategy and Performance — định nghĩa 5 components và 20 principles. Key concept: ERM không chỉ về risk avoidance mà về aligning risk appetite với strategy. Cybersecurity risk phải được đưa vào ERM framework — không tồn tại như một silo separate từ operational risk, financial risk, và strategic risk.

Risk Committee Governance: Risk Register — living document liệt kê tất cả identified risks, current rating (likelihood × impact), owner, và treatment plan. KRI (Key Risk Indicators) — leading indicators cảnh báo risk đang tăng TRƯỚC khi xảy ra incident. Ví dụ KRIs cho cyber risk: number of unpatched critical CVEs (tăng → risk tăng), phishing click rate, % endpoints với current EDR, số supplier security incidents. Risk Appetite Statement — Board-approved document định nghĩa "We will accept X risk but not Y risk" — ví dụ "Chúng ta chấp nhận risk of minor data breach nhưng không chấp nhận risk of regulatory fine > $1M."

3.2. Third-Party Risk Management (TPRM)

Vendor Risk Assessment: Phân loại vendors theo tier dựa trên data access và criticality: Tier 1 (xử lý PII/critical data, cao nhất) → annual onsite assessment, SOC 2 Type II required, contractual right-to-audit. Tier 2 → annual questionnaire, SOC 2 Type II hoặc equivalent. Tier 3 (minimal access) → initial assessment + periodic review. Questionnaire dựa trên SIG (Standardized Information Gathering) hoặc VSA (Vendor Security Alliance questionnaire) — chuẩn hóa để dễ compare.

SOC 2 Type II Review: Khi nhận SOC 2 Type II report từ vendor, CISO phải review: (1) Scope — trust service criteria covered (Security bắt buộc, Availability/Confidentiality/Processing Integrity/Privacy optional); (2) Test period — report phải cover ít nhất 6 tháng; (3) Exceptions — mọi exception/finding phải được read và assessed; (4) Subservice organizations — vendor có sub-processors nào không và coverage nào (carve-out vs. inclusive).

Contract Security Clauses: Minimum set: right to audit (on reasonable notice), breach notification requirement (24h hoặc 72h), data processing agreement (GDPR DPA nếu xử lý EU data), data return/destruction upon termination, security baseline requirements (encryption, MFA, vulnerability management), incident cooperation requirements, liability và indemnification caps, subcontracting restrictions.

3.3. Cyber Insurance — Policy Analysis & Coverage Optimization

Cyber insurance policy phải được CISO đọc kỹ — không phải chỉ Legal/Finance. Critical coverage areas: First-party coverage (business interruption, data recovery costs, ransom payment, forensic investigation, PR/notification costs). Third-party coverage (liability nếu customer data bị breach). Common exclusions: state-sponsored attacks (đang thay đổi sau NotPetya litigation), known vulnerabilities (nếu không patch trong thời gian specified), fraudulent transfer (thường cần separate crime policy).

CISO phải đảm bảo security controls align với underwriting requirements: insurers ngày càng require MFA, EDR, backups tested, IR plan documented — không có thì premium tăng hoặc coverage denied. Cuối cùng, insurance là risk transfer — không phải risk elimination. Residual risk sau insurance vẫn phải được managed.

4. Domain 4 — Threat Intelligence & Incident Management / Tình báo mối đe dọa & quản lý sự cố

4.1. Threat Intelligence Program — Intel Lifecycle

Threat intelligence được phân loại theo 4 types: Strategic (cho C-suite và Board — long-term trends, geopolitical context, nation-state threat actor profiles); Operational (cho security management — active campaigns, TTPs của threat actors đang target industry); Tactical (cho SOC analysts — attack techniques, malware families, infrastructure patterns); Technical (cho tools integration — IOCs: IPs, domains, hashes, YARA rules). ISSMP candidate phải hiểu mỗi type phục vụ audience khác nhau và cần format khác nhau.

Intel Lifecycle (6 phases): (1) Planning & Direction — định nghĩa intel requirements từ stakeholders: "CISO cần biết điều gì để đưa ra quyết định?" → Priority Intelligence Requirements (PIRs). (2) Collection — gather raw data từ multiple sources (OSINT, commercial feeds, ISAC, internal sensors). (3) Processing — normalize, de-duplicate, correlate, translate. (4) Analysis — apply analytical judgment, produce finished intel products. (5) Dissemination — deliver right intel to right audience in right format at right time. (6) Feedback — consumers evaluate usefulness → improve collection priorities.

4.2. ISAC Participation — STIX/TAXII & TLP

ISAC (Information Sharing and Analysis Centers) là sector-specific organizations chia sẻ threat intelligence giữa members: FS-ISAC (Financial Services), H-ISAC (Healthcare), E-ISAC (Energy), MS-ISAC (Multi-State — cho state/local governments). Membership benefits: early warning của sector-specific attacks, anonymized incident sharing, access to analyst expertise. CISO phải join relevant ISACs và có process để: consume incoming intel → enrich và contextualize → distribute internally → contribute back (information sharing là two-way).

STIX (Structured Threat Information eXpression) 2.1: JSON-based format để represent threat intel objects: Threat Actor, Attack Pattern (maps to MITRE ATT&CK), Campaign, Course of Action, Indicator (with pattern like [ipv4-addr:value = '1.2.3.4']), Malware, Vulnerability, Relationship. TAXII (Trusted Automated eXchange of Indicator Information) 2.1: Protocol để exchange STIX objects — Collection (set of objects) và Channel models. SIEM/TIP/Firewall consume TAXII feeds để auto-update detection rules và block lists.

TLP (Traffic Light Protocol) v2.0 — 4 levels: TLP:RED — chỉ share với named recipients trong meeting; TLP:AMBER+STRICT — share within organization only; TLP:AMBER — share within organization và với clients/customers trực tiếp liên quan; TLP:GREEN — share within community (không post public); TLP:CLEAR — no restriction. Security manager phải enforce TLP và train analysts về handling requirements.

4.3. Incident Management Program — CSIRT & Tabletop

CSIRT (Computer Security Incident Response Team) Structure: Mô hình phổ biến: Central CSIRT (enterprise-wide) + Distributed CSIRT (ở từng BU) phối hợp theo hub-and-spoke. IR team roles: IR Manager (điều phối), Lead Analyst (technical investigation), Forensics Analyst (evidence collection), Threat Intelligence Analyst (context), Legal Counsel (notification obligations), Communications Lead (internal/external), Business Continuity Coordinator. Không phải tất cả roles cần fulltime — nhiều có thể là on-call.

IR Policy & Playbooks: IR Policy define: scope, principles, team authority (AI: IR Manager có quyền isolate production system mà không cần VP approval nếu active ransomware). Playbooks — incident-type-specific procedures: Ransomware Playbook (contain → assess → decision on ransom → recover → improve), Phishing Playbook (analyze email → check for credential harvest → contain account → user notification → block IOCs), Data Breach Playbook (contain → assess scope → legal notification trigger → customer notification → forensics).

Tabletop Exercise Design: Hiệu quả tabletop cần: (1) Realistic scenario — dựa trên actual threat intel; (2) Right participants — decision-makers, không chỉ technical; (3) Injects — new information được introduce trong exercise để test adaptive decision-making; (4) Facilitator — giữ flow, không để technical details distract từ management decisions; (5) After-Action Review (AAR) — document gaps, assign remediation owners, set completion dates. Exercise types từ thấp đến cao: Tabletop → Functional → Full-scale.

4.4. Crisis Management & Regulatory Notification

Crisis Communication Plan: Phân biệt Internal communication (employees — "Here's what happened, here's what we're doing, here's what you should do") vs. External communication (media, customers, regulators — messaging phải be approved by Legal trước khi release). Holding statement — statement được prepared trước cho kịch bản major breach: "We are aware of a security incident and have initiated our incident response process. We take security seriously and are working to protect our customers. More information will be provided as it becomes available." Never say "We have no evidence of..." unless truly confirmed.

Regulatory Notification Timelines: GDPR (EU 2016/679) Article 33: 72 giờ sau khi aware of breach phải notify supervisory authority (DPA) — nếu likely to result in risk to individuals. Article 34: notify affected individuals "without undue delay" nếu high risk. SEC Cybersecurity Disclosure Rule (2023): Public companies phải disclose "material" cybersecurity incidents trong Form 8-K trong 4 business days sau determining incident is material. HIPAA Breach Notification: 60 days sau discovery cho individuals, 60 days sau year-end cho HHS nếu <500 individuals; 60 days sau discovery cho HHS nếu ≥500. PCI-DSS: Immediate notification to acquiring bank và card brands nếu suspected or confirmed cardholder data compromise.

5. Domain 5 — Contingency Management / Quản lý dự phòng

5.1. Business Continuity Management — ISO 22301 & BIA

ISO 22301:2019 (Security and Resilience — Business Continuity Management Systems) sử dụng cấu trúc Annex SL tương tự ISO 27001. PDCA cycle: Plan (establish BCM policy, scope, BIA, strategy) → Do (implement plans, training, exercises) → Check (monitor, measure, audit) → Act (continual improvement). Certification theo ISO 22301 ngày càng required trong procurement của large enterprises và government contracts.

BIA (Business Impact Analysis) — quy trình xác định critical business processes, RTO/RPO/MTD/MTPD cho từng process, và downstream dependencies. Methodology: (1) Interview business owners — "Nếu hệ thống này down 1h/4h/24h/1 week, tác động là gì?" (2) Quantify impact — financial (hourly revenue loss), regulatory (fine exposure), reputational. (3) Rank processes theo criticality. (4) Identify dependencies — applications, infrastructure, people, suppliers. (5) Define recovery requirements: RTO (max downtime), RPO (max data loss), MTD (Maximum Tolerable Downtime = outer limit beyond which mission fails), MTPD (Maximum Tolerable Period of Disruption — ISO 22301 term, equivalent to MTD).

5.2. DR Program — Testing Types & DR Metrics

DR Testing Types (từ low đến high fidelity): (1) Tabletop/Walk-through — team review DR plan together, discuss steps, identify gaps — low cost, no disruption risk; (2) Structured Walk-through (Parallel Test) — DR team activates DR environment IN PARALLEL với production — verify DR capability without switching over; (3) Simulation — specific scenarios simulated (ví dụ simulate primary DC power failure); (4) Full Interruption Test — production system is actually shut down, failover to DR — highest fidelity, highest risk, requires business owner approval; (5) Continuous/Automated Testing — infrastructure-as-code allows frequent automated failover testing (Netflix Chaos Monkey approach).

DR Metrics: RTO (Recovery Time Objective) — maximum acceptable downtime từ disruption to recovery. RPO (Recovery Point Objective) — maximum acceptable data loss measured in time (ví dụ RPO=1h → phải backup mỗi 1h). MTD (Maximum Tolerable Downtime) — absolute outer limit — after MTD, business mission fails (MTD ≥ RTO). MTPD (Maximum Tolerable Period of Disruption) — ISO 22301 equivalent của MTD. RTO phải luôn ≤ MTD — nếu không, DR plan sẽ không đủ để save business mission. Test kết quả phải được compare với RTO/RPO targets — "Achieved RTO 45 minutes vs. target RTO 30 minutes → gap of 15 minutes, root cause: backup restoration taking longer than expected."

5.3. Cyber Resilience — NIST CSF Recover Function & DORA

NIST CSF 2.0 Recover Function gồm 3 categories: RC.RP (Incident Recovery Plan Execution), RC.CO (Incident Recovery Communication), RC.IM (Incident Recovery Improvement). Key outcomes: services restored theo priorities defined trong recovery plan, recovery activities communicated to stakeholders, lessons learned incorporated into future response plans. CSF 2.0 (2024) thêm "Govern" function — nhấn mạnh governance là foundation cho tất cả 5 functions.

DORA (Digital Operational Resilience Act) — EU regulation 2022/2554, effective January 2025 — áp dụng cho financial entities tại EU: banks, insurers, investment firms, crypto-asset service providers, ICT third-party providers (kể cả cloud providers nếu critical). DORA yêu cầu: ICT risk management framework, incident classification and reporting (major ICT incidents báo cáo competent authority trong 4h initial report, 72h intermediate, 1 month final), digital operational resilience testing (annual TLPT — Threat-Led Penetration Testing cho significant entities), ICT third-party risk management (register of all ICT providers), information sharing on cyber threats.

Supply Chain Continuity: Identify critical supplier dependencies — single-source suppliers cho critical components/services phải được prioritized cho TPRM và continuity planning. Alternate sourcing strategy: pre-qualify alternate suppliers trước khi needed, maintain inventory buffer cho critical hardware components, architect applications để không lock-in một single cloud provider (multi-cloud strategy cho critical systems). Geographic diversification: không đặt primary và DR data center trong cùng một risk zone (flood plain, seismic zone, power grid region).

6. Domain 6 — Law, Ethics & Compliance Management / Pháp lý, đạo đức & tuân thủ

6.1. Compliance Program Management — Control Mapping

Compliance Calendar: Document liệt kê tất cả deadlines: quarterly vulnerability scans (PCI-DSS), annual penetration test (PCI-DSS, ISO 27001), annual security awareness training, SOC 2 Type II audit window, ISO 27001 surveillance audit, FedRAMP annual assessment, GDPR DPIA reviews. CISO phải ensure compliance calendar được integrated vào organizational calendar và ownership assigned.

Control Mapping (Unified Controls Framework): Thay vì implement separate controls cho mỗi regulation, map regulations tới common controls. Ví dụ: control "Enforce MFA cho privileged accounts" thỏa mãn: PCI-DSS v4.0 Req. 8.4.2, ISO 27001 Annex A 5.17, NIST SP 800-53 IA-2(1)(2), HIPAA §164.312(d), SOC 2 CC6.1. One control → many compliance requirements → giảm audit fatigue và redundant implementations. Tools: MetricStream, ServiceNow GRC, OneTrust, Archer.

Evidence Collection Automation: Manual evidence collection cho audits là bottleneck — automating thông qua: API integration với cloud platforms (AWS Config → auto-evidence cho encryption controls), SIEM → auto-log exports cho audit period, CMDB → auto-inventory for asset management controls, Vulnerability scanners → scan reports as evidence. Evidence được stored trong GRC tool với version control và audit trail.

6.2. Legal Holds & eDiscovery

Legal Hold Process: Khi có litigation threat hoặc regulatory investigation, General Counsel issue legal hold. Security/IT phải: (1) Identify custodians (people whose data is relevant) và data sources; (2) Preserve data — suspend auto-deletion policies, snapshot backups; (3) Notify custodians — cannot delete relevant data; (4) Collect ESI (Electronically Stored Information) — email, files, logs, chat. Legal hold violation (spoliation) có thể result in adverse inference instructions tại tòa — cực kỳ nguy hiểm về pháp lý.

Chain of Custody cho Digital Evidence: Mỗi piece of digital evidence phải có documented chain of custody: ai thu thập, khi nào, từ đâu, như thế nào, ai handle sau đó. Hash values (SHA-256) được tính cho tất cả evidence files — verify integrity tại mỗi transfer point. Forensic copies (không phải working copies) được work với — original evidence được stored và preserved. Failure to maintain chain of custody có thể make evidence inadmissible.

6.3. Privacy Program Integration — GDPR DPO & DPIA

DPO (Data Protection Officer) theo GDPR Article 37 — bắt buộc khi: (a) tổ chức là public authority, (b) core activities involve large-scale systematic monitoring of individuals, (c) core activities involve large-scale processing of special categories data. DPO phải independent (không nhận instructions về việc exercise tasks), có expertise về data protection law, accessible to data subjects. DPO báo cáo thẳng lên highest management level — không thể bị terminated for performing DPO tasks.

DPIA (Data Protection Impact Assessment) theo GDPR Article 35 — bắt buộc trước khi bắt đầu processing có high risk, đặc biệt: systematic and extensive profiling, large-scale processing of special categories, systematic monitoring of publicly accessible areas. DPIA process: describe processing → assess necessity and proportionality → identify and assess risks to rights and freedoms → identify risk mitigation measures → consult DPO. Nếu residual risk vẫn high sau mitigation → phải consult supervisory authority (DPA) trước khi proceed.

6.4. Professional Ethics — (ISC)² Code of Ethics

(ISC)² Code of Ethics gồm Preamble và 4 canons theo priority order: Canon 1: Protect society, the common good, necessary public trust and confidence, and the infrastructure. Canon 2: Act honorably, honestly, justly, responsibly, and legally. Canon 3: Provide diligent and competent service to principals. Canon 4: Advance and protect the profession. Priority order quan trọng: Canon 1 (society) > Canon 2 (ethical behavior) > Canon 3 (employer/client) > Canon 4 (profession). Khi có conflict, CISSP phải prioritize theo order này — ví dụ nếu employer yêu cầu làm gì đó harmful to society, Canon 1 override Canon 3.

Conflicts of Interest & Whistleblower: Security manager phải disclose conflicts of interest (ví dụ đang evaluate vendor mà họ có financial interest). Whistleblower protection — nhiều jurisdictions (EU Whistleblower Directive, US SOX, Dodd-Frank) bảo vệ người báo cáo vi phạm bảo mật/fraud. ISSMP candidate phải biết khi nào phải escalate hoặc report — even if employer object — theo Canon 1.

7. Bài thực hành / Hands-on labs

🖥️ Nền tảng / Platform: Windows 11 · Python 3.11
🛠️ Công cụ / Tools: Python · matplotlib · pandas · Word/Excel templates

Lab 1 — Xây dựng Security KRI Dashboard bằng Python + Matplotlib

OS: Windows 11 / Ubuntu 22.04 · Tool: Python 3.11, matplotlib, numpy. Mục tiêu: Tạo KRI dashboard 6 metrics với trend lines và threshold indicators.

  1. Cài đặt dependencies:
    pip install matplotlib numpy pandas --quiet
    python3 -c "import matplotlib; print(f'matplotlib {matplotlib.__version__} ready')"
  2. Tạo KRI dashboard script:
    cat > /tmp/security-kri-dashboard.py <<'PYTHON'
    #!/usr/bin/env python3
    """Security KRI Dashboard — ISSMP Lab 1"""
    import matplotlib
    matplotlib.use('Agg')
    import matplotlib.pyplot as plt
    import matplotlib.patches as mpatches
    import numpy as np
    
    # Sample 6-month KRI data (Jan-Jun 2026)
    months = ['Jan', 'Feb', 'Mar', 'Apr', 'May', 'Jun']
    
    kris = {
        'Unpatched Critical CVEs': {
            'values': [45, 38, 29, 22, 18, 12],
            'threshold': 20,
            'threshold_type': 'max',  # below threshold = good
            'unit': 'count',
            'color': '#ef4444'
        },
        'Phishing Click Rate (%)': {
            'values': [8.2, 7.5, 6.8, 5.9, 4.7, 3.8],
            'threshold': 5.0,
            'threshold_type': 'max',
            'unit': '%',
            'color': '#f97316'
        },
        'EDR Coverage (%)': {
            'values': [72, 78, 83, 88, 93, 97],
            'threshold': 95,
            'threshold_type': 'min',  # above threshold = good
            'unit': '%',
            'color': '#22c55e'
        },
        'MTTD — Hours': {
            'values': [18, 15, 12, 9, 6, 4],
            'threshold': 8,
            'threshold_type': 'max',
            'unit': 'hours',
            'color': '#3b82f6'
        },
        'MTTR — Hours': {
            'values': [72, 60, 48, 36, 28, 20],
            'threshold': 24,
            'threshold_type': 'max',
            'unit': 'hours',
            'color': '#8b5cf6'
        },
        'Security Training Completion (%)': {
            'values': [45, 58, 71, 82, 91, 98],
            'threshold': 90,
            'threshold_type': 'min',
            'unit': '%',
            'color': '#14b8a6'
        }
    }
    
    fig, axes = plt.subplots(2, 3, figsize=(16, 10))
    fig.suptitle('Security KRI Dashboard — Q1/Q2 2026\nHoaTranLab Security Program',
                 fontsize=14, fontweight='bold', y=0.98)
    
    for idx, (kri_name, kri_data) in enumerate(kris.items()):
        ax = axes[idx // 3][idx % 3]
        values = kri_data['values']
        threshold = kri_data['threshold']
        color = kri_data['color']
    
        # Plot trend line
        ax.plot(months, values, marker='o', linewidth=2.5, color=color,
                markersize=7, markerfacecolor='white', markeredgewidth=2.5)
    
        # Fill area under curve
        ax.fill_between(range(len(months)), values, alpha=0.1, color=color)
    
        # Threshold line
        ax.axhline(y=threshold, color='red', linestyle='--', linewidth=1.5,
                   alpha=0.8, label=f'Target: {threshold}{kri_data["unit"]}')
    
        # Color background: green=good, red=bad for last month
        last_val = values[-1]
        if kri_data['threshold_type'] == 'max':
            bg_ok = last_val <= threshold
        else:
            bg_ok = last_val >= threshold
    
        ax.set_facecolor('#f0fdf4' if bg_ok else '#fef2f2')
    
        # Labels
        ax.set_title(kri_name, fontsize=9, fontweight='bold', pad=8)
        ax.set_xticks(range(len(months)))
        ax.set_xticklabels(months, fontsize=8)
        ax.tick_params(axis='y', labelsize=8)
        ax.legend(fontsize=7)
        ax.grid(True, alpha=0.3, linestyle=':')
    
        # Annotate last value
        ax.annotate(f'{last_val}{kri_data["unit"]}',
                    xy=(len(months)-1, values[-1]),
                    xytext=(8, 0), textcoords='offset points',
                    fontsize=9, fontweight='bold', color=color)
    
    plt.tight_layout(rect=[0, 0, 1, 0.96])
    plt.savefig('/tmp/security-kri-dashboard.png', dpi=150, bbox_inches='tight')
    print("KRI Dashboard saved: /tmp/security-kri-dashboard.png")
    print("\nKRI Summary (June 2026):")
    for name, data in kris.items():
        last = data['values'][-1]
        thr = data['threshold']
        if data['threshold_type'] == 'max':
            status = "✅ ON TARGET" if last <= thr else "❌ EXCEEDS TARGET"
        else:
            status = "✅ ON TARGET" if last >= thr else "❌ BELOW TARGET"
        print(f"  {name:<40}: {last}{data['unit']:<8} {status}")
    PYTHON
    
    python3 /tmp/security-kri-dashboard.py

✅ Kết quả mong đợi / Expected output: Console in KRI Summary cho June 2026 với 6 KRIs — hầu hết "ON TARGET" (vì data được thiết kế để show improvement trend). File /tmp/security-kri-dashboard.png (khoảng 200KB+) là dashboard 2×3 grid với 6 subplots. Mỗi plot có: trend line theo màu sắc riêng, đường threshold đỏ đứt nét, background xanh (on target) hoặc đỏ (off target), annotation giá trị tháng gần nhất. Dashboard thể hiện improvement trajectory — đây là narrative CISO cần khi báo cáo Board về security program progress.

Lab 2 — Tabletop Exercise Simulation: Ransomware Scenario với Decision Trees

OS: Ubuntu 22.04 / Windows 11 · Tool: Python 3. Mục tiêu: Simulate interactive ransomware tabletop exercise với decision branches và consequence tracking.

  1. Chạy tabletop simulation script:
    cat > /tmp/ransomware-tabletop.py <<'PYTHON'
    #!/usr/bin/env python3
    """Ransomware Tabletop Exercise Simulator — ISSMP Lab 2"""
    import time, datetime
    
    def print_separator():
        print("\n" + "="*70 + "\n")
    
    def inject(time_str, message, details=None):
        """Simulate a tabletop inject"""
        print(f"\n⚡ INJECT [{time_str}]")
        print(f"   {message}")
        if details:
            for d in details:
                print(f"   • {d}")
    
    def decision(question, options):
        """Present decision point and collect response"""
        print(f"\n🔴 DECISION REQUIRED:")
        print(f"   {question}")
        for i, (opt, consequence) in enumerate(options, 1):
            print(f"   [{i}] {opt}")
        while True:
            choice = input("   Your decision (1-{}): ".format(len(options))).strip()
            if choice.isdigit() and 1 <= int(choice) <= len(options):
                chosen = options[int(choice)-1]
                print(f"\n   ✓ Decision recorded: {chosen[0]}")
                print(f"   📊 Consequence: {chosen[1]}")
                return int(choice)
            print("   Invalid input — please enter a number.")
    
    # === EXERCISE START ===
    print_separator()
    print("🎯 RANSOMWARE INCIDENT TABLETOP EXERCISE")
    print("   Scenario: LockBit 3.0 variant attack on corporate file servers")
    print("   Organization: HoaTranLab Corp (2,500 employees)")
    print("   Exercise Date:", datetime.date.today().isoformat())
    print("   Participants: CISO, IR Manager, Legal, Communications, IT Ops, Finance")
    print_separator()
    input("   [Press Enter to begin the exercise...]")
    
    decisions = []
    timeline = []
    
    # INJECT 1
    inject("T+0 (03:47 AM)", "SOC Tier 1 analyst receives automated alert: 'Unusual file encryption activity detected on FS-PROD-01 (file server). 847 files renamed with .locked extension in last 10 minutes.'",
        ["Alert confidence: HIGH (behavioral detection + multiple IOCs)", "Affected system: FS-PROD-01 — Production file server (400GB, 2,800 users have access)", "No user reports yet — 3:47 AM on weekday"])
    
    c1 = decision("How do you escalate and who do you wake up at 3:47 AM?",
        [("Wake CISO + IR Manager only. Monitor for 30 min before wider escalation.",
          "Risk: 30 min delay allows further encryption. ~85,000 additional files could be encrypted."),
         ("Immediately activate full IR team: CISO, Legal, IR Manager, IT Ops lead.",
          "Best practice. Ransomware spreads fast — 30 min can mean difference between 10% and 50% data encrypted."),
         ("Let Tier 1 handle it until morning shift. No weekend escalation policy.",
          "CRITICAL RISK: By morning, entire network may be encrypted. This violates IR policy.")])
    decisions.append(("Escalation", c1))
    timeline.append(("T+0", "Alert detected, escalation decision made"))
    
    print()
    input("   [Press Enter for next inject...]")
    
    # INJECT 2
    inject("T+15 min", "IR Manager online. IT Ops confirms: ransom note found on FS-PROD-01 desktop. Attacker demands 50 BTC (~$3.2M). Lateral movement detected: 3 additional servers now showing IOCs.",
        ["Ransom note: 'LockBit 3.0 — Your data is encrypted. Pay within 72 hours or data published on leak site.'",
         "New IOC: beaconing to 185.220.101.x (known TOR exit node) from FILESRV-02",
         "IT Ops estimates: if unchecked, full AD forest could be compromised in ~2 hours"])
    
    c2 = decision("IMMEDIATE containment — which action first?",
        [("Isolate only the known affected servers (FS-PROD-01, FILESRV-02) from network.",
          "Moderate: Slows spread but attacker may have already pivoted to other hosts."),
         ("Emergency network segmentation: isolate entire file server VLAN from rest of network.",
          "Good: Stops lateral movement in file server segment. May impact some business operations."),
         ("Shut down entire corporate network to stop all lateral movement.",
          "Extreme: Prevents spread but causes full business outage. Use only if organization-wide compromise confirmed.")])
    decisions.append(("Containment", c2))
    timeline.append(("T+15m", "Lateral movement confirmed, containment decision made"))
    
    input("   [Press Enter for next inject...]")
    
    # INJECT 3
    inject("T+45 min", "Legal Counsel online. Key questions: (1) Is customer PII on the affected servers? (2) Do we need to notify regulators? IT confirms: FS-PROD-01 has HR data including employee PII (2,200 records) and some customer contract files.",
        ["HR data: employee names, SSNs, bank account numbers (payroll data)",
         "Company operates in EU — GDPR applicable",
         "Some customers are US government agencies — notification requirements unclear"])
    
    c3 = decision("Regulatory notification — what is the immediate legal obligation?",
        [("Wait until full forensic investigation complete before notifying anyone.",
          "HIGH RISK: GDPR Article 33 requires DPA notification within 72 HOURS of becoming aware. Waiting for full investigation = violation."),
         ("Start GDPR 72-hour clock now. Assign DPA notification to Legal. Preserve all evidence. Brief CISO on SEC disclosure if applicable.",
          "CORRECT: GDPR clock starts when you become aware of breach. Legal must file preliminary notification within 72h even without full details."),
         ("Notify all employees and customers immediately via company email.",
          "PREMATURE: Public notification before containment may alert attacker and cause panic. GDPR notifications go to DPA first, then individuals.")])
    decisions.append(("Regulatory notification", c3))
    timeline.append(("T+45m", "PII confirmed on affected systems, GDPR clock started"))
    
    input("   [Press Enter for next inject...]")
    
    # INJECT 4
    inject("T+2 hours", "CISO Brief: Ransom demand is 50 BTC. CFO on call: cyber insurance policy has $5M coverage but $500K deductible. Backups exist but last verified backup is 48 HOURS OLD (RPO violation). Estimated recovery without paying: 7-10 days.",
        ["RTO for core business: 4 hours (from BIA)", "Actual estimated recovery: 7-10 days (SEVERE RTO violation)",
         "Ransom payment: legal in your jurisdiction but may not recover all data", "Threat actor has reputation for providing decryption keys when paid"])
    
    c4 = decision("Ransom payment decision:",
        [("Pay the ransom immediately to restore operations fastest.",
          "Risky: No guarantee of decryption key. Funds criminal enterprise. May violate OFAC sanctions if TOR payment to sanctioned entity."),
         ("Do not pay. Begin recovery from backups immediately despite 7-10 day timeline. Notify stakeholders.",
          "Recommended by FBI/CISA. Avoids funding criminals. 48-hour data loss is painful but recoverable. Board and insurers informed."),
         ("Negotiate with threat actor while simultaneously beginning backup recovery.",
          "Pragmatic hedge: buys time, may reduce demand. Legal must confirm no OFAC issues. Do not stop recovery while negotiating.")])
    decisions.append(("Ransom payment", c4))
    timeline.append(("T+2h", "Ransom decision made, recovery initiated"))
    
    # === AFTER ACTION ===
    print_separator()
    print("📋 AFTER-ACTION REVIEW — Exercise Summary")
    print(f"   Exercise Duration: ~45 minutes simulated / {len(decisions)} decision points")
    print()
    print("Decision Log:")
    for i, (topic, choice) in enumerate(decisions, 1):
        options = {1: "Option A", 2: "Option B", 3: "Option C"}
        print(f"   {i}. {topic}: {options.get(choice, 'Unknown')} selected")
    print()
    print("Incident Timeline:")
    for t, event in timeline:
        print(f"   {t:<10}: {event}")
    print()
    print("Key Gaps Identified During Exercise (template — fill in actual findings):")
    gaps = [
        "Backup verification policy: last verified backup was 48h old — violates RPO of 4h for file servers",
        "GDPR notification process: team unsure who files DPA notification and what information to include",
        "Ransom payment decision authority: no pre-defined policy on who can approve/deny payment",
        "After-hours escalation: no documented on-call rotation for IR team wake-up",
        "Network segmentation: VLAN isolation procedure not tested — IT estimated 20+ minutes to execute"
    ]
    for i, gap in enumerate(gaps, 1):
        print(f"   GAP-{i:02d}: {gap}")
    print()
    print("Recommended Remediation Owners:")
    print("   GAP-01: IT Operations — backup verification automation by 2026-07-01")
    print("   GAP-02: Legal Counsel — GDPR notification template and runbook by 2026-06-15")
    print("   GAP-03: CISO + CEO — ransom payment policy approval by 2026-06-30")
    print_separator()
    PYTHON
    
    python3 /tmp/ransomware-tabletop.py

✅ Kết quả mong đợi / Expected output: Interactive exercise chạy 4 injects với prompt đợi user input quyết định (1/2/3). After-action review in ra: Decision Log với 4 decisions đã chọn, Incident Timeline với 4 events, 5 Gaps được identify với recommended remediation owners. Đây là format chuẩn của tabletop exercise AAR document mà CISO trình lên Steering Committee. Mỗi Gap có assigned owner và target date — gaps phải được closed trước tabletop exercise tiếp theo.

Lab 3 — Vendor Risk Assessment Questionnaire dựa trên ISO 27001 Annex A

OS: Ubuntu 22.04 / Windows 11 · Tool: Python 3. Mục tiêu: Tạo vendor risk assessment questionnaire tự động score và categorize vendors.

  1. Tạo và chạy questionnaire engine:
    cat > /tmp/vendor-risk-assessment.py <<'PYTHON'
    #!/usr/bin/env python3
    """Vendor Risk Assessment Questionnaire — ISO 27001 Annex A based"""
    
    QUESTIONS = [
        # (question_text, iso_control, weight, response_options: [(text, score)])
        ("Does your organization have an ISO 27001 or SOC 2 Type II certification?",
         "A.5.31 (Legal requirements)", 3,
         [("ISO 27001 certified (active)", 10), ("SOC 2 Type II (active)", 9),
          ("In progress / planned", 5), ("No certification", 0)]),
    
        ("How often do you perform vulnerability assessments and penetration testing?",
         "A.8.8 (Vulnerability management)", 2,
         [("Quarterly or more frequent", 10), ("Annually", 7),
          ("Ad-hoc / when required", 3), ("Never", 0)]),
    
        ("Do you enforce Multi-Factor Authentication (MFA) for all privileged access?",
         "A.8.5 (Secure authentication)", 3,
         [("Yes — all privileged and remote access require MFA", 10),
          ("Yes — privileged access only", 7),
          ("Planned within 6 months", 4),
          ("No MFA deployed", 0)]),
    
        ("How is data encrypted at rest for data you process on our behalf?",
         "A.8.24 (Cryptography)", 2,
         [("AES-256 or equivalent, with key management system", 10),
          ("Encryption at rest, key management informal", 7),
          ("Partial encryption", 4),
          ("No encryption at rest", 0)]),
    
        ("What is your Security Incident notification timeline to clients?",
         "A.5.24 (Incident planning)", 3,
         [("Within 24 hours of confirmed incident", 10),
          ("Within 72 hours", 8),
          ("Within 7 days", 4),
          ("No defined notification SLA", 0)]),
    
        ("Do you have a documented Business Continuity Plan tested within the last 12 months?",
         "A.5.29 (Business continuity)", 2,
         [("Yes — tested and documented, results available", 10),
          ("Yes — documented but not tested", 6),
          ("Informal plan exists", 3),
          ("No BCP", 0)]),
    
        ("How do you screen employees with access to our data (background checks)?",
         "A.6.1 (Screening)", 2,
         [("Pre-employment + periodic checks, including criminal background", 10),
          ("Pre-employment only", 7),
          ("Manager reference checks only", 3),
          ("No formal screening", 0)]),
    
        ("Do you have a formal patch management process with defined SLAs?",
         "A.8.8 (Patch management)", 2,
         [("Critical patches within 24h, high within 7 days — tracked", 10),
          ("Monthly patching cycle", 6),
          ("Ad-hoc patching", 3),
          ("No formal patch management", 0)]),
    ]
    
    def run_assessment():
        print("=" * 65)
        print("VENDOR RISK ASSESSMENT QUESTIONNAIRE")
        print("Based on ISO 27001:2022 Annex A Controls")
        print("=" * 65)
        vendor_name = input("\nVendor Organization Name: ").strip() or "Sample Vendor Co."
        assessor = input("Assessor Name: ").strip() or "Security Analyst"
        print()
    
        total_score = 0
        max_score = 0
        responses = []
    
        for i, (question, control, weight, options) in enumerate(QUESTIONS, 1):
            print(f"\nQ{i}: {question}")
            print(f"     ISO Control: {control} | Weight: {weight}x")
            for j, (opt_text, opt_score) in enumerate(options, 1):
                print(f"     [{j}] {opt_text}")
    
            while True:
                choice = input(f"     Response (1-{len(options)}): ").strip()
                if choice.isdigit() and 1 <= int(choice) <= len(options):
                    chosen_text, chosen_score = options[int(choice)-1]
                    weighted_score = chosen_score * weight
                    total_score += weighted_score
                    max_score += 10 * weight
                    responses.append((question, control, chosen_text, chosen_score, weight, weighted_score))
                    print(f"     ✓ Recorded (raw score: {chosen_score}/10, weighted: {weighted_score}/{10*weight})")
                    break
                print("     Invalid — please enter a number.")
    
        # Calculate results
        percentage = (total_score / max_score) * 100
    
        print("\n" + "=" * 65)
        print(f"ASSESSMENT RESULTS: {vendor_name}")
        print("=" * 65)
        print(f"Total Score: {total_score}/{max_score} ({percentage:.1f}%)")
    
        if percentage >= 80:
            rating = "LOW RISK ✅"
            tier = "Tier 3 — Standard annual review"
        elif percentage >= 60:
            rating = "MEDIUM RISK ⚠️"
            tier = "Tier 2 — Enhanced review, request SOC 2"
        elif percentage >= 40:
            rating = "HIGH RISK 🔴"
            tier = "Tier 1 — Onsite assessment required before contract"
        else:
            rating = "CRITICAL RISK ❌"
            tier = "Do Not Engage — security posture insufficient"
    
        print(f"Risk Rating: {rating}")
        print(f"Recommended Tier: {tier}")
        print()
        print("Question-level breakdown:")
        for q_text, control, response, raw, weight, weighted in responses:
            status = "✅" if raw >= 7 else ("⚠️" if raw >= 4 else "❌")
            print(f"  {status} {control:<30} | Response score: {raw}/10")
        print(f"\nAssessor: {assessor} | Date: 2026-05-24")
        print("=" * 65)
    
    run_assessment()
    PYTHON
    
    python3 /tmp/vendor-risk-assessment.py

✅ Kết quả mong đợi / Expected output: Interactive questionnaire 8 câu hỏi — nhập vendor name, assessor, và chọn 1-4 cho mỗi câu. Kết quả cuối: Total Score dạng X/Y (percent%), Risk Rating (LOW/MEDIUM/HIGH/CRITICAL), và Recommended Vendor Tier với action. Question-level breakdown hiển thị ✅/⚠️/❌ cho từng control. Ví dụ: vendor chọn toàn option tốt nhất → score ~100%, LOW RISK, Tier 3. Vendor thiếu MFA và không có cert → score ~40%, HIGH RISK, Tier 1 — onsite assessment required.

Lab 4 — Xây dựng 90-Day CISO Onboarding Security Assessment Plan

OS: Ubuntu 22.04 / Windows 11 · Tool: Python 3. Mục tiêu: Generate structured 90-day onboarding plan với milestones và deliverables.

  1. Tạo onboarding plan generator:
    cat > /tmp/ciso-90day-plan.py <<'PYTHON'
    #!/usr/bin/env python3
    """90-Day CISO Onboarding Security Assessment Plan Generator"""
    import datetime
    
    today = datetime.date.today()
    
    def week_date(start, week_offset, day_offset=0):
        return (start + datetime.timedelta(weeks=week_offset, days=day_offset)).strftime("%d/%m/%Y")
    
    start = today
    plan = f"""
    ╔══════════════════════════════════════════════════════════════════════╗
    ║          90-DAY CISO ONBOARDING — SECURITY ASSESSMENT PLAN           ║
    ║   Organization: [Target Org — 5,000 employees]                       ║
    ║   CISO Start Date: {today.strftime("%d/%m/%Y"):<49}║
    ║   Objective: Assess security posture, build relationships, plan      ║
    ╚══════════════════════════════════════════════════════════════════════╝
    
    ═══════════════════════════════════════════
    PHASE 1: LISTEN & LEARN (Days 1-30)
    Goal: Understand current state — NO major changes yet
    ═══════════════════════════════════════════
    
    Week 1 (by {week_date(start, 0, 6)}):
      □ Meet all direct reports (1:1 with each security team member)
      □ Review existing security policies and standards (collect all available)
      □ Request access to: SIEM, vulnerability scanner, asset inventory
      □ Read last 3 audit reports (internal + external) and last 3 incident reports
      □ Meet CIO, CFO, CRO, General Counsel (15-min introductions)
      Deliverable: Stakeholder map with initial impressions
    
    Week 2 (by {week_date(start, 1, 6)}):
      □ Deep-dive with SOC Manager: review alert volume, detection coverage, escalation process
      □ Walk through last 3 major incidents with IR team (what happened, how detected, how resolved)
      □ Review current security architecture diagram (if exists)
      □ Interview key business unit leaders: "What are your security concerns?"
      □ Review security budget: OpEx/CapEx breakdown, contract renewals upcoming
      Deliverable: Business unit risk concern register
    
    Week 3 (by {week_date(start, 2, 6)}):
      □ Assess vulnerability management: time-to-remediation by severity, backlog size
      □ Review IAM posture: orphaned accounts, privileged account inventory, MFA coverage
      □ Evaluate endpoint security: EDR coverage, encryption status, patch compliance
      □ Review cloud security posture: Defender for Cloud / AWS Security Hub findings
      □ Assess third-party risk program (if any exists)
      Deliverable: Technical security baseline assessment (DRAFT)
    
    Week 4 (by {week_date(start, 3, 6)}):
      □ Assess compliance program: active frameworks, upcoming audits, open findings
      □ Review security awareness training: completion rates, phishing test results
      □ Evaluate security tooling: what tools exist, licensing, integration quality
      □ Complete threat landscape assessment: who are the threat actors targeting this org?
      □ Brief CEO: "Here is what I have learned so far"
      Deliverable: 30-Day Assessment Report (CONFIDENTIAL) — present to CEO/CIO
    
    ═══════════════════════════════════════════
    PHASE 2: ASSESS & PRIORITIZE (Days 31-60)
    Goal: Gap analysis and risk-ranked roadmap
    ═══════════════════════════════════════════
    
    Week 5-6 (by {week_date(start, 5, 6)}):
      □ Conduct formal maturity assessment (NIST CSF or ISO 27001 gap analysis)
      □ Run FAIR quantitative risk analysis on top 5 risk scenarios
      □ Map current controls to compliance requirements (PCI-DSS, GDPR, etc.)
      □ Identify single points of failure in security architecture
      □ Build risk register with quantified risk values
      Deliverable: Risk Register v1.0 with FAIR scores
    
    Week 7-8 (by {week_date(start, 7, 6)}):
      □ Prioritize initiatives by risk-reduction-per-dollar
      □ Identify quick wins (0-90 days): MFA gaps, critical patch backlog, orphaned accounts
      □ Design 3-year security transformation roadmap (high level)
      □ Build budget request for Year 1 initiatives
      □ Present roadmap draft to Security Steering Committee for feedback
      Deliverable: 3-Year Security Roadmap (DRAFT) + Year 1 budget request
    
    ═══════════════════════════════════════════
    PHASE 3: DELIVER QUICK WINS (Days 61-90)
    Goal: Demonstrate value, implement first changes
    ═══════════════════════════════════════════
    
    Week 9-11 (by {week_date(start, 10, 6)}):
      □ Execute top 3 quick wins (example: enforce MFA for all admins, close critical vulns)
      □ Establish security metrics dashboard (KRIs — weekly reporting)
      □ Formalize Security Steering Committee cadence
      □ Establish vendor risk assessment process for new vendors
      □ Update/create Incident Response Policy and top 3 playbooks
      Deliverable: Quick Win implementation evidence + updated IR playbooks
    
    Week 12-13 (by {week_date(start, 12, 6)}):
      □ Present 90-Day Assessment Report to Board/Audit Committee
      □ Get Board approval on 3-year security roadmap and Year 1 budget
      □ Publish security program charter (RACI, governance structure)
      □ Set OKRs for security team for next 2 quarters
      □ Schedule first security tabletop exercise within 30 days
      Deliverable: 90-Day Board Presentation + Approved Security Roadmap
    
    ═══════════════════════════════════════════
    90-DAY ASSESSMENT REPORT STRUCTURE
    (Board Presentation Outline)
    ═══════════════════════════════════════════
    
    1. Executive Summary (2 slides)
       - Overall security rating: [Red/Yellow/Green] with trend direction
       - Top 3 risks requiring immediate attention
    
    2. Current State Assessment (4 slides)
       - Security maturity scores by domain vs. industry benchmark
       - Top vulnerabilities (quantified in financial terms using FAIR)
       - Compliance gaps and exposure
    
    3. Threat Landscape (2 slides)
       - Who is targeting us and how
       - Recent industry incidents relevant to our sector
    
    4. Roadmap & Investment (3 slides)
       - 3-year transformation roadmap with milestones
       - Year 1 priorities and ROI projection
       - Budget request and business case
    
    5. Governance Proposal (1 slide)
       - Security Steering Committee cadence
       - RACI and accountability framework
    
    Generated: {today.strftime("%d/%m/%Y")} | Template version 1.0
    """
    
    with open("/tmp/ciso-90day-onboarding-plan.md", "w") as f:
        f.write(plan)
    print(plan)
    print(f"\nPlan saved: /tmp/ciso-90day-onboarding-plan.md")
    print(f"Total plan lines: {len(plan.splitlines())}")
    PYTHON
    
    python3 /tmp/ciso-90day-plan.py

✅ Kết quả mong đợi / Expected output: Console in full 90-day plan với actual dates tính từ today (ví dụ Week 1 deadline = 7 ngày từ hôm nay). Plan gồm 3 phases, 13 tuần hoạt động, 50+ specific tasks với checkbox format. 5 key deliverables được defined: 30-Day Assessment Report, Risk Register v1.0, 3-Year Roadmap, Quick Win Evidence, 90-Day Board Presentation. Board Presentation Structure 5-section outline. File markdown được lưu tại /tmp/ciso-90day-onboarding-plan.md. Đây là template thực tế mà CISO mới nhậm chức tại Fortune 500 company sử dụng.

8. Tình huống doanh nghiệp / Real-world scenario

Bối cảnh:

Nguyễn Minh Tuấn vừa được bổ nhiệm làm CISO của TechCorp Vietnam — tập đoàn công nghệ 5.000 nhân viên hoạt động tại 4 quốc gia (Việt Nam, Singapore, Nhật Bản, Úc) với doanh thu $800M/năm. Sau 3 tháng đầu tiên, ông phát hiện thực trạng: 12 công cụ bảo mật riêng lẻ không tích hợp, không có CISO nào trước đó (security do IT Manager kiêm nhiệm), IR plan cũ 5 năm chưa được test, 47 critical CVEs tồn đọng hơn 90 ngày, không có SOC (incident detection thủ công), và công ty sắp mua lại một công ty startup ở Singapore. Board yêu cầu ông trình bày kế hoạch 18 tháng tại cuộc họp tháng tới.

Phương án theo ISSMP framework:

  1. Immediate Actions (tuần 1-2): Patch 47 critical CVEs — sử dụng emergency change process; disable tất cả inactive accounts (identity hygiene); brief CEO về risk exposure dạng financial (FAIR analysis rough estimate); phân công IR coordinator tạm thời từ existing team.
  2. Foundation (tháng 1-3): Establish Security Steering Committee với CEO buy-in; deploy Microsoft Defender (EDR) enterprise-wide — quick win với existing M365 license; migrate SIEM về Microsoft Sentinel (consolidate 12 tools); viết lại IR Policy và 3 playbooks (ransomware, phishing, data breach); complete M&A cyber due diligence cho Singapore startup.
  3. Build Maturity (tháng 4-9): Deploy SOAR (Microsoft Sentinel Playbooks) để automate top 5 playbooks; establish formal threat intel program — join FS-ISAC (TechCorp có financial services clients); implement ISO 31000 ERM framework — integrate cyber risk vào corporate risk register; launch security awareness program với phishing simulation; complete ISO 27001 gap analysis.
  4. Optimize (tháng 10-18): Target ISO 27001 certification (demonstrates maturity to customers); implement FAIR-based quantitative risk reporting cho Board (quarterly); establish red team program (annual); lead first cross-country tabletop exercise covering Vietnam + Singapore + Japan; file first ISO 27001 Stage 1 audit.
  5. Board Communication: Monthly KRI dashboard (6 metrics, trend-based), quarterly risk report (FAIR quantified top 5 risks), annual comprehensive security program review. Framing cho Board: "Từ fragmented ad-hoc security lên mature managed program — ROI: expected loss reduction từ $8.5M/year xuống $2.1M/year theo FAIR model."

Bài học ISSMP: CISO thành công không phải người giỏi kỹ thuật nhất — mà là người có thể translate risk thành business language, build coalitions với C-suite và Board, và deliver measurable outcomes trong thời hạn cam kết. Security là people problem trước khi là technology problem.

9. Tự kiểm tra / Knowledge check

  1. CISO cần báo cáo Board về security posture hàng quý. Board hỏi: "Chúng ta có bảo mật hơn năm ngoái không?" — Sử dụng KRI framework, hãy nêu 5 metrics cụ thể (với units) mà CISO nên track và present, và giải thích tại sao mỗi metric có ý nghĩa cho board-level audience.
  2. Phân biệt ISO 31000 và COSO ERM 2017 về scope và primary audience. Khi tổ chức đã có COSO ERM, CISO phải làm gì để integrate cybersecurity risk vào COSO ERM framework mà không tạo duplicate risk management process?
  3. Một vendor Tier 1 (xử lý PII) gửi SOC 2 Type II report có 3 exceptions: (a) backup testing not performed trong test period, (b) one terminated employee account not disabled for 45 days, (c) encryption key rotation not following policy. Bạn đánh giá như thế nào và yêu cầu gì từ vendor trước khi renew contract?
  4. Threat intelligence có 4 types (Strategic/Operational/Tactical/Technical). Với một phishing campaign mới của APT-41 đang target Vietnamese banking sector (nguồn từ FS-ISAC, TLP:AMBER), CISO phải disseminate intel này đến các audience nào ở mức độ detail nào? Describe format cho mỗi audience.
  5. GDPR Article 33 yêu cầu notify DPA trong 72 giờ. Trong thực tế, tổ chức thường không biết đầy đủ thông tin trong 72 giờ đầu. Làm thế nào để comply với Article 33 trong khi điều tra vẫn đang tiến hành? Notification phải chứa thông tin gì theo Article 33(3)?
  6. RTO của core banking system là 4 giờ. DR test gần nhất đạt actual recovery time 7 giờ. Identify ít nhất 3 potential root causes và describe recovery strategy adjustment nào có thể giảm actual recovery time xuống dưới 4 giờ mà không thay đổi hardware infrastructure.
  7. (ISC)² Code of Ethics Canon 1 (Protect society) vs. Canon 3 (Serve principals). Tình huống: Employer yêu cầu CISO không disclose một data breach nhỏ (200 records) vì lo ngại reputational damage, dù incident có GDPR notification obligations. ISSMP candidate phải xử lý thế nào? Reference specific Canon và explain reasoning.
Chương 2: ISSEP Mục lục Phase 6
Thực hành trên công cụPython 3.11 · matplotlib · GRC templates
Nền tảngWindows 11 · Ubuntu 22.04 LTS
Thời điểm phát hànhQ4/2026
Ngày biên soạn24/05/2026
Người biên soạnTrần Văn Hòa MCT
Phiên bảnv1.0
Zalo